Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2727▼ 513 respecto a la semana anterior
Críticas / altas1294▼ 200 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
797 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.39% | — | Wpbookingcalendar WP Booking Calendar | 14/1/2025 | 17/6/2026 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'booking' shortcode in all versions up to, and including, 10.9.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (7.5) | 0.64% | — | Codepeople Appointment Booking Calendar | 13/1/2025 | 17/6/2026 | The Appointment Booking Calendar Plugin and Scheduling Plugin WordPress plugin before 1.1.23 export settings functionality exports data to a public folder, with an easily guessable file name, allowing unauthenticated attackers to access the exported files (if they exist). | |
| Aplazada | Media (6.5) | 0.29% | — | Pixelite WP FullcalendarAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Marcus (aka @msykes) WP FullCalendar wp-fullcalendar allows Stored XSS.This issue affects WP FullCalendar: from n/a through <= 1.5. | |
| Aplazada | Media (6.1) | 0.37% | — | Booking CalendarAIBooking Calendar PROAI | 7/1/2025 | 17/6/2026 | The Booking Calendar and Booking Calendar Pro plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the ‘calendar_id’ parameter in all versions up to, and including, 3.2.19 and 11.2.19 respectively, due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (4.3) | 0.19% | — | Stellarwp THE Events CalendarAI | 2/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in StellarWP The Events Calendar the-events-calendar allows Cross Site Request Forgery.This issue affects The Events Calendar: from n/a through <= 6.5.1.4. | |
| Analizada | Media (6.5) | 0.49% | — | Wpdevart Booking Calendar | 24/12/2024 | 17/6/2026 | The Booking Calendar WpDevArt plugin is vulnerable to time-based, blind SQL injection via the `id` parameter in the “wpdevart_booking_calendar” shortcode in versions up to, and including, 3.2.19 due to insufficient escaping on the user-supplied parameter and lack of sufficient preparation on the existing SQL query.… | |
| Modificada | Media (5.4) | 0.23% | — | Vcita Online Booking & Scheduling Calendar | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Cross Site Request Forgery.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <= 4.5. | |
| Analizada | Media (5.3) | 1.1% | 💥 Exploit | Stellarwp THE Events Calendar | 16/12/2024 | 17/6/2026 | The Events Calendar WordPress plugin before 6.8.2.1 is missing access checks in the REST API, allowing for unauthenticated users to access information about password protected events. | |
| Aplazada | Media (5.3) | 0.63% | — | Theeventscalendar THE Events CalendarAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in The Events Calendar The Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects The Events Calendar: from n/a through 6.1.2.2. | |
| Aplazada | Media (6.4) | 0.36% | — | ADD Infos TO THE Events CalendarAI | 12/12/2024 | 17/6/2026 | The Add infos to the events calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fuss' shortcode in all versions up to, and including, 1.4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (4.3) | 0.56% | — | Codepeople Booking Calendar Contact FormAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople Booking Calendar Contact Form allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking Calendar Contact Form: from n/a through 1.2.34. | |
| Modificada | Alta (8.8) | 0.50% | — | Wpdevart Booking Calendar | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in WpDevArt Booking calendar, Appointment Booking System allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Booking calendar, Appointment Booking System: from n/a through 3.2.3. | |
| Aplazada | Baja (3.8) | 0.47% | — | Codepeople CP Multi View Event CalendarAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in CodePeople CP Multi View Event Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects CP Multi View Event Calendar : from n/a through 1.4.13. | |
| Analizada | Media (5.4) | 0.26% | — | Vcita Online Booking & Scheduling Calendar | 6/12/2024 | 17/6/2026 | The Online Booking & Scheduling Calendar for WordPress by vcita plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the vcita_save_user_data_callback() function in all versions up to, and including, 4.5.1. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.8) | 0.31% | — | Wpbookingcalendar WP Booking Calendar | 3/12/2024 | 17/6/2026 | The WP Booking Calendar WordPress plugin before 10.6.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Analizada | Media (6.1) | 0.46% | — | Wpbeginner Sugar Calendar | 26/11/2024 | 17/6/2026 | The Sugar Calendar – Simple Event Management plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.3.0. This makes it possible for unauthenticated attackers to inject… | |
| Aplazada | Alta (7.2) | 0.47% | — | Booking CalendarAI | 26/11/2024 | 17/6/2026 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 3.2.15 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Aplazada | Media (6.5) | 0.32% | — | Masashi Takizawa Multi-day Booking CalendarAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Masashi Takizawa Multi-day Booking Calendar multi-day-booking-calendar allows DOM-Based XSS.This issue affects Multi-day Booking Calendar: from n/a through <= 1.0.1. | |
| Analizada | Media (5.4) | 0.33% | — | K5N Webcalendar | 15/11/2024 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in craigk5n/webcalendar version 1.3.0. The vulnerability occurs in the 'Report Name' input field while creating a new report. An attacker can inject malicious scripts, which are then executed in the context of other users who view the report, potentially leading… | |
| Analizada | Crítica (9.6) | 0.69% | — | Roundupwp Registrations FOR THE Events Calendar | 8/11/2024 | 17/6/2026 | The Registrations for the Events Calendar WordPress plugin before 2.12.4 does not sanitise and escape some parameters when accepting event registrations, which could allow unauthenticated users to perform Cross-Site Scripting attacks. | |
| Analizada | Media (4.8) | 0.35% | — | Wpbookingcalendar WP Booking Calendar | 7/11/2024 | 17/6/2026 | The WP Booking Calendar WordPress plugin before 10.6.3 does not sanitise and escape some of its Widgets settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Aplazada | Media (6.4) | 0.39% | — | Roundupwp Registrations FOR THE Events CalendarAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Roundup WP Registrations for the Events Calendar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Registrations for the Events Calendar: from n/a through 2.12.1. | |
| Modificada | Media (6.1) | 0.33% | — | Vcita Online Booking & Scheduling Calendar | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in vcita Online Booking & Scheduling Calendar for WordPress by vcita meeting-scheduler-by-vcita allows Reflected XSS.This issue affects Online Booking & Scheduling Calendar for WordPress by vcita: from n/a through <=… | |
| Aplazada | Alta (7.5) | 0.57% | — | Innate Images LLC VR CalendarAIInnate Images LLC VR Calendar SyncAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Innate Images LLC VR Calendar vr-calendar-sync allows PHP Local File Inclusion.This issue affects VR Calendar: from n/a through <= 2.4.0. | |
| Analizada | Media (4.8) | 0.32% | — | Wpbookingcalendar WP Booking Calendar | 4/10/2024 | 17/6/2026 | The WP Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 10.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to… |